CVE-2017-10299: Infoleak
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10299?
CVE-2017-10299 is considered a critical vulnerability that can be easily exploited by low privileged attackers.
How do I fix CVE-2017-10299?
To fix CVE-2017-10299, upgrade Oracle Agile PLM to versions 9.3.7 or later as recommended by Oracle.
What systems are affected by CVE-2017-10299?
CVE-2017-10299 affects Oracle Agile PLM versions 9.3.5 and 9.3.6.
Can CVE-2017-10299 be exploited remotely?
Yes, CVE-2017-10299 can be exploited remotely via HTTP by an attacker with low privileges.
What is the impact of CVE-2017-10299 on Oracle Agile PLM?
The impact of CVE-2017-10299 allows unauthorized access and potential compromise of Oracle Agile PLM.